CVE-2026-16102 Details
Description
A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user account and a limited Initial Access Token can exploit this to forge administrative roles in their access token. This allows the attacker to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.
A vulnerability exists in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The issue arises because the default DCR policy does not properly validate the claim path for User Property mappers. This oversight allows attackers to write values to sensitive internal claim locations. An attacker with a standard user account and a limited Initial Access Token can exploit this flaw to forge administrative roles in their access token. Consequently, the attacker could take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:50846 | [email protected] | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:50847 | [email protected] | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:50848 | [email protected] | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:50849 | [email protected] | Vendor Advisory |
| https://access.redhat.com/security/cve/CVE-2026-16102 | [email protected] | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2501735 | [email protected] | Issue Tracking |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-551 | Incorrect Behavior Order: Authorization Before Parsing and Canonicalization | [email protected] |
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| redhat build of keycloak | >= 26.4, < 26.4.14 >= 26.6, < 26.6.5 |
CPE
Remediation
| |
| redhat data grid | 8.0 |
CPE
Remediation
| |
| redhat jboss enterprise application platform expansion pack | All versions |
CPE
Remediation
| |
| redhat single sign-on | 7.0 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 21, 2026 | CVE Modified | [email protected] |
| Aug 20, 2026 | CVE Modified | [email protected] |
| Aug 11, 2026 | Initial Analysis | [email protected] |
| Aug 5, 2026 | CVE Modified | [email protected] |
| Aug 5, 2026 | CVE Modified | [email protected] |
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | New CVE Received | [email protected] |